VPN or Zero Trust? Network security for hybrid working environments

Rethinking security in hybrid working environments

VPN or Zero Trust: what really protects your network

In the past, the corporate network was clearly demarcated. Today, teams work remotely, applications run in the cloud and the internet is becoming the new corporate network. Traditional VPNs are reaching their limits here. This is exactly where Zero Trust comes in.

In a nutshell:

  • Changing IT landscape: SaaS applications shift data processing from the data center to the cloud
  • VPNs under pressure: high administration costs and poor user experience make them unattractive
  • Zero Trust principle: access is no longer based on location, but on identity, device and context
  • SASE integration: combination of SD WAN and Security as a Service creates scalable, secure connections
  • Hybrid use: Same access and same security, whether in the office or working from home

SAVECALL supports companies in the transition from traditional VPN structures to modern Zero Trust architectures that combine security and performance.

The question: How do you protect your hybrid working environment against modern threats?

In the past, corporate networks developed around the respective locations, offices, factory floors and data centers. Client-server applications were mainly used, with applications mostly hosted in private or public data centers such as Equinix. Remote workers were a rarity and were tunneled into the corporate network via VPN. Such VPN solutions were not particularly popular with either users or administrators, but were accepted as a necessary evil. This created a situation in which everything within the network was secure and everything outside the network was insecure.

The transformation of IT

In recent years, there has been a major change in IT. Thanks to the use of Software-as-a-Service, fewer and fewer applications were operated in the company’s own or rented data center. Most SaaS solutions are provided via the internet and operated in the browser. As a result, security requirements have changed fundamentally. There is no longer a clear boundary between secure and insecure. Applications and data are now outside the network boundaries of the organization, so it became less important to defend the boundaries and more important to protect the applications, the data and the users, no matter where they were.

Another change has taken place since the start of the pandemic months. As many have been forced to work from home, and many continue to do so, we are essentially using the internet as our new corporate network. As a result, tried and tested WANs such as MPLS are being used less and less for site connectivity. If all applications are provided via the internet, the question arises as to whether a classic WAN is still needed at all.

VPN: obstacle or added value?

Despite all further developments, some basic truths still apply. A network is needed to connect all applications, users and devices. However, expectations of this network have changed. Users expect fast, user-friendly applications that work the same way on any device, anywhere. They see VPNs as an obstacle to their usual user experience.

At the same time, the internet has not become more secure. With the easy availability of attack tools and botnets, as well as the proliferation of ransomware in corporate IT environments, threats continue to increase. Network security is therefore no longer just a problem at the network edge, it is a problem for all areas.

Zero Trust as a solution

The future of IT security is called Zero Trust. But isolated Zero Trust solutions, with their virtual security appliances, still create choke points in a WAN, which has a negative impact on the user experience.

The goal must therefore be to find a unified SD-WAN and Security-as-a-Service solution. Such solutions can eliminate bottlenecks in the network and provide seamless, scalable Zero Trust Security as a Service. With such a solution, every user has access to the services they need, regardless of whether they are working from home or in the office.

Frank Frommknecht, Key Account Consultant at SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for over 20 years in selecting and optimizing their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and finding the right solution strategically.

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

Sources

  • Gartner: Market Guide for Zero Trust Network Access
  • Thales: study on remote work and security mindset among IT leaders
  • SAVECALL: SASE solutions for businesses

Frequently asked questions about VPN and Zero Trust

Why do classic VPNs reach their limits with hybrid work models?

Applications increasingly run in the cloud instead of on-premises, and the internet is becoming the new corporate network. VPNs cause high administrative overhead and a poor user experience because they were designed for a world with a clearly defined network edge that no longer exists.

What distinguishes Zero Trust from classic VPN logic?

With a classic VPN, the principle is: secure inside the network, insecure outside. Zero Trust reverses this principle: access is no longer based on location, but on identity, device and context, regardless of whether someone is working in the office or from home.

What role does SASE play in the shift to Zero Trust?

SASE combines SD-WAN and Security as a Service into one unified solution. This eliminates the bottlenecks that isolated Zero Trust appliances otherwise create in the WAN, and offers seamless, scalable Zero Trust Security as a Service for all users.

Why is classic WAN like MPLS used less often for site connectivity?

As many employees work permanently from home, the internet effectively becomes the new corporate network. If all applications are delivered via the internet anyway, the need for classic, location-bound WAN technologies such as MPLS decreases.

Has the internet become safer as classic network boundaries disappear?

No, quite the opposite. Attack tools, botnets and ransomware are easily available and on the rise. Network security is therefore no longer just an edge problem, it affects every area of a company equally.

How does SAVECALL support the shift from VPN to Zero Trust?

SAVECALL supports companies in the transition from traditional VPN structures to modern Zero Trust architectures that combine security and performance, using a unified SD-WAN and Security-as-a-Service solution.

Articles you might also like

What drives you forward – & what drives

Book a free expert consultation